Backdoor

Should I remove “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 0F4401F99676640A83F6.mlw
path: /opt/CAPEv2/storage/binaries/06b01b91daeaaa50b8ad13e35a9ad4b6c005a235cf7ce0896f5c7f5b4580edf8
crc32: 7C77976F
md5: 0f4401f99676640a83f67aecb0e2724a
sha1: 9ef160c1dfd895e45216801d216b64fe29f350f1
sha256: 06b01b91daeaaa50b8ad13e35a9ad4b6c005a235cf7ce0896f5c7f5b4580edf8
sha512: 68e382609e7ec2472afec6c98e9a0fc7d3f25bcf58366e83ce3369ced63d6eed29eb784edc9ab69943a294551c5cd60df06e7e5ae645141e18e7a9754a667752
ssdeep: 1536:ODpawe3jlTad6TKgND0pm3Ecp27z+5xgJqXXVjqpRGxBu/Ub0VkVNK:OnUjlzLZ0pIEAEqgSQXGbu/Ub0+NK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C7939D7374590F71D742C3B02001D5A12A4A97E8D37DC283A7C3976F9653A07AFB9EA8
sha3_384: 138a7484853b4d05b43fbf165f674114d8737f43fef63896e09cfc02a2c58737db5c73258522f260d306f5428a2d9dc4
ep_bytes: 90909060909067e80000000090909058
timestamp: 1984-11-04 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGenPack:Trojan.GenericKDZ.103285
ClamAVWin.Trojan.Crypted-29
FireEyeGeneric.mg.0f4401f99676640a
SkyhighBehavesLike.Win32.Generic.nc
McAfeeTrojan-FVOK!0F4401F99676
MalwarebytesGeneric.Malware.AI.DDS
VIPREGenPack:Trojan.GenericKDZ.103285
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.1dfd89
ArcabitGenPack:Trojan.Generic.D19375
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGenPack:Trojan.GenericKDZ.103285
NANO-AntivirusTrojan.Win32.Padodor.jzgiyz
AvastWin32:Padodor-V [Trj]
TencentTrojan-Proxy.Win32.Qukart.kj
TACHYONBackdoor/W32.Padodor
SophosMal/Padodor-A
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.Padodor.Win32.1043482
Trapminemalicious.high.ml.score
EmsisoftGenPack:Trojan.GenericKDZ.103285 (B)
IkarusTrojan.Crypt
JiangminTrojanProxy.Qukart.dxtq
GoogleDetected
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGenPack:Trojan.GenericKDZ.103285
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.60D6216921
ALYacGenPack:Trojan.GenericKDZ.103285
MAXmalware (ai score=83)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:4:vX3Ud0w8LLO)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment